Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
2026-03-30T01:24:10Z•233ef0fe0edfc8d2d1f38942600757ba71adb6556c8e3c7a4a5a3086e88c5183
AitMCVE-2025-53521CVE-2026-3055KEVPyPIactive-exploitationbackdoorchina-linkedcloudflare-turnstile-evasion','ransomware','GenieLocker','telecocredential-harvestdark_swordexploitiOS-exploitiran-linkedknown-exploited-vulnerabilitymemory-overreadopen-vsxphishingpre-publish-bypassrussia-linkedspear-phishingstate-sponsoredsupply-chainvs-code-extensionvulnerability
What happened
A batch of The Hacker News reports (late Mar 2026) highlights pervasive, high-impact activity: Iran-linked Handala breached FBI Director Kash Patel’s personal email and leaked materials and also deployed a wiper against Stryker; multiple critical vulnerabilities are under active reconnaissance/exploitation (Citrix NetScaler memory overread CVE-2026-3055, and F5 BIG-IP APM CVE-2025-53521 added to CISA’s KEV); and Russian-linked TA446 is using the DarkSword iOS exploit kit in targeted spear-phishing. Supply-chain and software distribution compromises by TeamPCP (malicious telnyx PyPI packages, l
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 233ef0fe0edfc8d2d1f38942600757ba71adb6556c8e3c7a4a5a3086e88c5183
- Enrichment time
- 2026-03-30T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.